What is SASE/SSE? Secure Networking from the Cloud, Clearly Explained
The way companies work has changed fundamentally in recent years: applications live in the cloud, employees work from anywhere, and sites, data centers, and mobile devices must be securely connected to each other at all times. Traditional network models that route all traffic through a central data center are reaching their limits. This is exactly where SASE comes in: an approach that merges networking and security into a single, cloud-based service. Secure networking from the cloud — clearly explained, piece by piece.
The network specialist Cloudflare explains the concept clearly in its learning article "What is SASE?". We summarize the key points and put into perspective what SASE/SSE means for modern, distributed companies.
What is SASE?
SASE stands for "Secure Access Service Edge" (pronounced "sassy"). The term was coined in 2019 by the analyst firm Gartner. The basic idea: network functions and security functions that previously consisted of many individual products are merged into one unified service and delivered from the cloud, close to the user and regardless of where that user happens to be.
Specifically, Gartner described the approach in the report "The Future of Network Security Is in the Cloud" (August 2019), written by the analysts Neil MacDonald, Lawrence Orans, and Joe Skorupa. The core statement: network and security functions that were traditionally run separately as individual appliances converge into a single, cloud-native service. The decisive criterion is no longer the network topology but the identity of users, devices, and services, together with the relevant context (location, device posture, risk situation) and the applicable security and compliance requirements. Gartner expected rapid adoption early on and saw SASE on its way from a niche term to a defining architecture for networking and security.
Instead of laboriously routing traffic to a central location and back again, SASE moves inspection and protection out to the boundary of the network, the so-called "edge." Access is decided by the identity of the user and the device, no longer by location. That fits a world in which the office is just one of many access points.
The building blocks of SASE
SASE is not a single product but the bundling of several coordinated technologies into one platform. We explain the most important building blocks one by one below.
SD-WAN (Software-Defined WAN)
SD-WAN forms the network foundation of SASE. Instead of coupling sites via expensive, rigid MPLS leased lines, SD-WAN steers traffic in software across any type of line (broadband, fiber, or cellular via LTE/5G) and dynamically selects the best path for each application. Time-critical traffic such as voice and video conferencing is prioritized, while non-critical data takes cheaper routes. This lowers line costs, increases resilience, and connects new sites in hours instead of weeks.
Secure Web Gateway (SWG)
A Secure Web Gateway inspects outbound web traffic before it reaches the open internet. It blocks known malicious and phishing sites, filters malware out of downloads, enforces usage policies (such as permitted website categories), and can open up encrypted traffic for security inspection. Users are thus protected from web-based threats regardless of location, in the office as well as at home.
Remote Browser Isolation (RBI)
Remote Browser Isolation moves browsing from the endpoint into an isolated environment in the cloud. The user sees only a secure, interactive visual stream of the website. Active code, scripts, and any malware run exclusively in the sealed-off remote session and never reach the device. Especially with risky or unknown websites, links from emails, and the handling of sensitive data, RBI prevents web-based threats from ever reaching the endpoint in the first place.
Cloud Access Security Broker (CASB)
The Cloud Access Security Broker creates visibility and control over the use of cloud services such as Microsoft 365, Google Workspace, or Salesforce. It reveals which applications are actually in use (including unapproved "shadow IT") and governs who may upload or download which data. SaaS usage thus remains transparent and controllable instead of growing unchecked.
Zero Trust Network Access (ZTNA)
Zero Trust Network Access replaces the classic VPN with identity-based access following the principle of "never trust, always verify." Instead of opening the entire network to a user after login, every access request is evaluated individually: per user, per application, taking device posture and context into account. Applications remain invisible from the outside and only become reachable after a successful check, which sharply limits lateral movement if something goes wrong.
Firewall-as-a-Service (FWaaS)
Firewall-as-a-Service moves complete firewall functionality into the cloud, from packet filtering and intrusion prevention to application control at layer 7. Because the firewall runs centrally as a service, dedicated hardware at each site becomes unnecessary, and rules apply uniformly to all users and locations. The service takes care of maintenance, updates, and scaling, with no on-site intervention.
Data Loss Prevention (DLP)
Data Loss Prevention prevents the unintended outflow of sensitive data. Rules detect, for example, credit card or HR data and confidential documents, and stop them from leaving the company via web uploads, unauthorized cloud services, or other channels. In a SASE/SSE platform, DLP applies uniform specifications across channels, that is, across web, cloud apps, and data transfers.
It is the interplay of these components that makes SASE what it is: networking and security are controlled together through one platform instead of being managed separately.
How SASE works
At the center of SASE is a globally distributed network of points of presence (PoPs). When a user accesses an application, their traffic is inspected, secured, and forwarded at the nearest PoP. The laborious detour through a central data center disappears.
Two effects follow: first, latency drops because the path gets shorter. Applications feel faster as a result. Second, security inspection applies equally everywhere, whether someone works in the office, at home, or on the road. Security travels with the user instead of being tied to a location.
SASE versus the classic network model
Classic corporate networks often follow a hub-and-spoke model: all traffic from all sites is carried over expensive leased lines to a central data center, inspected there, and sent back. As long as most applications lived in the company's own data center, that worked. In a cloud world, however, this detour means unnecessary latency, high costs, and a bottleneck that grows with every new site and every cloud service.
SASE inverts this principle: security and control move into the cloud and to the edge of the network. The detour disappears, and the architecture scales with demand. New sites or users can be connected without setting up dedicated hardware at each location.
SASE and SSE: what is the difference?
Alongside SASE, the term SSE frequently comes up: "Security Service Edge." SSE describes the pure security part of SASE, essentially Secure Web Gateway, CASB, and Zero Trust Network Access. What is missing is the network component, in particular SD-WAN. Gartner introduced SSE as a term in its own right in 2021.
Put simply: SSE is security from the cloud, SASE is security plus networking from the cloud. Many companies start with the security part (SSE) and add the network side step by step. That is why both terms are often mentioned together as "SASE/SSE."
The benefits of SASE/SSE
Moving to a SASE/SSE architecture brings a number of concrete benefits:
- Less complexity: one platform instead of many individual products from different vendors, managed in one consistent way.
- Lower costs: less hardware at the sites and no more expensive leased lines take pressure off the budget.
- Better performance: inspection at the nearest edge location instead of a detour through a central data center reduces latency.
- Rigorous Zero Trust: access is checked per user and application, without blanket trust in the internal network.
- Smaller attack surface: services can no longer be discovered from outside; access is granted only after a successful check.
- Easy scaling: new sites, users, and cloud services can be connected quickly and without on-site hardware.
SASE/SSE with KAEMI
As convincing as the concept is, the value only materializes with the right implementation and ongoing management. This is where we come in. As a managed security service provider and Cloudflare partner, we plan, implement, and manage SASE/SSE architectures for mid-sized companies, requirements-driven and from a single source.
In practice, that means we assess which building blocks and technologies fit your specific requirements, integrate them cleanly into the existing environment, and then take on monitoring, hardening, and further development, with clearly agreed response times and a dedicated point of contact. This turns an architecture concept into a reliable, secure managed service.
More on how we deliver SASE/SSE as a managed service can be found on our Secure Access Service Edge page .
A compact overview of all Cloudflare products for Zero Trust & SASE/SSE is available on our Cloudflare page .
This article draws on the Cloudflare learning article "What is SASE?" .